computer-automation
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npx -y @midscene/computer@1to download and execute code directly from the npm registry. This introduces a dependency on third-party software that is fetched at runtime, creating a supply chain risk if the package or registry is compromised. - [DATA_EXFILTRATION]: To perform its tasks, the skill captures screenshots of the entire desktop via the
take_screenshotcommand. These images may contain sensitive personal data, credentials, or private documents visible on the screen, which are then transmitted to external AI model providers for processing. - [INDIRECT_PROMPT_INJECTION]: The skill interprets visual content on the screen to decide on actions. If a user opens a malicious website, document, or email that contains adversarial instructions, the agent might interpret that text as a command and execute it.
- Ingestion points: Visual screenshots of the desktop captured by the
take_screenshotcommand (SKILL.md). - Boundary markers: No explicit visual delimiters or filtering instructions are provided to help the agent distinguish between user instructions and text appearing on the screen.
- Capability inventory: Full mouse and keyboard control via the
actcommand and arbitrary shell command execution via theBashtool. - Sanitization: No sanitization or validation of the text extracted from screen captures is performed before being used for action planning.
- [COMMAND_EXECUTION]: The skill relies on the
Bashtool to execute its core automation CLI commands. - [CREDENTIALS_UNSAFE]: The skill requires sensitive information such as AI model API keys and RDP credentials. While it advises against hardcoding secrets, it suggests passing passwords in shell variables within CLI flags (e.g.,
--password "$RDP_PASSWORD"), which can potentially leak sensitive data into process listings or shell history logs.
Audit Metadata